When going from AD to Workgroup you'll need to create local profiles on each computer for each person if they move between the computers. If they never use the other computer, then it likely won't be needed. Only their own profile on their computer
You should have a local administer account on all machines regardless as a just in case, use a complex password and disable it if you feel at risk. Or - will the users have local administrator rights to their computer allowing them to do and install anything. (risky).
File Server - or just call it a NAS. Yes,.. separate passwords here can be a bother,.. but 'easy enough' Even an off-domain computer can access a file share if you have domain credentials - I do so all the time at the office on a fresh imaged PC.
Here at home I have a dozen computers that are non-domain and non-Microsoft Sign-on and a central NAS. Some folders in the NAS are open READ (movies, music) some are password access with username. And separate UserNames from the Desktop.